CVE-2015-8947Improper Restriction of Operations within the Bounds of a Memory Buffer in Harfbuzz

Severity
7.6HIGHNVD
EPSS
0.5%
top 34.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 17

Description

hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HExploitability: 2.8 | Impact: 4.7

Affected Packages5 packages

debiandebian/harfbuzz< harfbuzz 1.2.6-1 (bookworm)
Debianharfbuzz_project/harfbuzz< 1.2.6-1+3
Ubuntuharfbuzz_project/harfbuzz< 0.9.27-1ubuntu1.1+1
NVDgoogle/chrome47.0.2526.106

🔴Vulnerability Details

5
GHSA
GHSA-vx72-qhm5-54jj: Multiple unspecified vulnerabilities in HarfBuzz before 12022-05-17
GHSA
GHSA-8w8v-wf57-7pwq: hb-ot-layout-gpos-table2022-05-14
OSV
harfbuzz vulnerabilities2016-08-24
OSV
CVE-2015-8947: hb-ot-layout-gpos-table2016-07-19
OSV
CVE-2016-2052: Multiple unspecified vulnerabilities in HarfBuzz before 12016-01-25

📋Vendor Advisories

5
Ubuntu
HarfBuzz vulnerabilities2016-08-24
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.62016-01-24
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.62016-01-24
Debian
CVE-2016-2052: harfbuzz - Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google...2016
Debian
CVE-2015-8947: harfbuzz - hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to c...2015

💬Community

4
Bugzilla
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [epel-7]2016-07-21
Bugzilla
CVE-2015-8947 CVE-2016-2052 mingw-harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]2016-07-21
Bugzilla
CVE-2015-8947 CVE-2016-2052 harfbuzz: chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6 [fedora-all]2016-07-21
Bugzilla
CVE-2016-2052 CVE-2015-8947 chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.62016-01-25
CVE-2015-8947 — Debian Harfbuzz vulnerability | cvebase